| File name: | JRT.exe |
| Full analysis: | https://app.any.run/tasks/050ee029-a444-45d6-9c4f-2e6a44cfdc04 |
| Verdict: | Malicious activity |
| Analysis date: | October 23, 2023, 15:33:48 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | E40542C4CC75E658A4615BFEFB308570 |
| SHA1: | 961A8C8C332494201E4F275FE1F50ABAE99140B3 |
| SHA256: | 2000ACF98EF0AC1A2D75C91586B5F30A2BC3ECE6E92388B324614C93A0645CF5 |
| SSDEEP: | 98304:ofPy7aaBPMFofjtZ7dvirsNhwx5SWAxVILeVnW7Hlr8AKpG7l6I3keTo7HUlmn1m:Agd |
| .exe | | | Generic Win/DOS Executable (50) |
|---|---|---|
| .exe | | | DOS Executable Generic (49.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2010:06:27 09:06:38+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 8 |
| CodeSize: | 70656 |
| InitializedDataSize: | 52224 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x11def |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 8.1.4.0 |
| ProductVersionNumber: | 8.1.4.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| CompanyName: | Malwarebytes |
| FileDescription: | Junkware Removal Tool |
| FileVersion: | 8.1.4 |
| ProductVersion: | 8.1.4 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 316 | REG QUERY "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion" /v ProductName | C:\Windows\System32\reg.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Console Tool Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 568 | "C:\Users\admin\AppData\Local\Temp\jrt\WGET.DAT" -q "http://data-cdn.mbamupdates.com/v1/tools/jrt/jrtnewmd5" | C:\Users\admin\AppData\Local\Temp\jrt\WGET.DAT | cmd.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 1 Modules
| |||||||||||||||
| 584 | C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\jrt\get.bat" " | C:\Windows\System32\cmd.exe | — | JRT.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1484 | "C:\Users\admin\AppData\Local\Temp\JRT.exe" | C:\Users\admin\AppData\Local\Temp\JRT.exe | explorer.exe | ||||||||||||
User: admin Company: Malwarebytes Integrity Level: HIGH Description: Junkware Removal Tool Exit code: 0 Version: 8.1.4 Modules
| |||||||||||||||
| 1824 | "C:\Users\admin\AppData\Local\Temp\JRT.exe" | C:\Users\admin\AppData\Local\Temp\JRT.exe | — | explorer.exe | |||||||||||
User: admin Company: Malwarebytes Integrity Level: MEDIUM Description: Junkware Removal Tool Exit code: 3221226540 Version: 8.1.4 Modules
| |||||||||||||||
| 1904 | C:\Windows\system32\net1 session | C:\Windows\System32\net1.exe | — | net.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Net Command Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2100 | C:\Windows\system32\cmd.exe /c REG QUERY "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ComputerName\ActiveComputerName" /v ComputerName 2>NUL | C:\Windows\System32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2448 | net session | C:\Windows\System32\net.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Net Command Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2464 | FC "C:\Users\admin\AppData\Local\Temp\jrt\jrtnewmd5" "C:\Users\admin\AppData\Local\Temp\jrt\jrtcurrentmd5" | C:\Windows\System32\fc.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: DOS 5 File Compare Utility Exit code: 2 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2952 | FIND "Windows XP" | C:\Windows\System32\find.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Find String (grep) Utility Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (1484) JRT.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (1484) JRT.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (1484) JRT.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (1484) JRT.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1484 | JRT.exe | C:\Users\admin\AppData\Local\Temp\jrt\bl_chrstrg.cfg | text | |
MD5:EBDFDE9F11720DFC627933F37E8AE319 | SHA256:613DEC5AE47C9FCC4EFF4E50FE811FD41A9442796A57DBB0E63FBE36178C0663 | |||
| 1484 | JRT.exe | C:\Users\admin\AppData\Local\Temp\jrt\bl_appinit.cfg | text | |
MD5:CC6A968CCDA289BE7B69E039646D0BC9 | SHA256:95691814D105108152B96E41D0F0FF30462D0A060AF32431089C312604C235B6 | |||
| 1484 | JRT.exe | C:\Users\admin\AppData\Local\Temp\jrt\nfo\shortcut.txt | text | |
MD5:3A26827485C683AACD1E0194F34A0CFA | SHA256:094E2FA2C6DF5FEE039BA345067BA5B2C22E8C54CA4A8D7B35E86A91C1E8E320 | |||
| 1484 | JRT.exe | C:\Users\admin\AppData\Local\Temp\jrt\nfo\NirCmd.chm | binary | |
MD5:66729EFE2819E71C060AF7FD49732C28 | SHA256:E050308C4A297F637A848109D719C65A62F6AB6ED0D854D026CC2DF257515D32 | |||
| 1484 | JRT.exe | C:\Users\admin\AppData\Local\Temp\jrt\nfo\sed.txt | text | |
MD5:13171419A6D180FDD8B52CEAE16DDADF | SHA256:C8A8A4818146DD8960849C2B028E565A94C8D4E036E01E1E28E0FA91D42C7E43 | |||
| 1484 | JRT.exe | C:\Users\admin\AppData\Local\Temp\jrt\clean_shortcut.vbs | text | |
MD5:FA73FE2C0D3C62E8732A71282E2E491C | SHA256:449B9F2DC6B67A6ECCF0FBE16FF91AF50EFB57E0978393A2C3F1B3FAFD1189D9 | |||
| 1484 | JRT.exe | C:\Users\admin\AppData\Local\Temp\jrt\get.bat | text | |
MD5:6142E0A5C78FA8B63993357AF48D7AB9 | SHA256:F793FA295E1598556A6B91EB73B68D825D5EDBCB0A764D9D58A570A6A4B5BF0F | |||
| 1484 | JRT.exe | C:\Users\admin\AppData\Local\Temp\jrt\bl_foldersC.cfg | text | |
MD5:AE4C96D8F463036C8EFEA6A0565C2F50 | SHA256:69EB2C63BAB14F7E91CA4483E741583D8F6B8994F79C53FDF17CE6AF7774738F | |||
| 1484 | JRT.exe | C:\Users\admin\AppData\Local\Temp\jrt\bl_chrext.cfg | text | |
MD5:935ED2949D1ECEAC23C52564CBA49529 | SHA256:DBEDB3193DDA09AC6DF38A640A08BEE54041D020D46223AD7B3F297E4253360F | |||
| 1484 | JRT.exe | C:\Users\admin\AppData\Local\Temp\jrt\bl_ffplugin.cfg | text | |
MD5:6C0A5B19478B5CC273E9DE5C2AA0E165 | SHA256:691E2F088E116FF729CF64535C2FE4389D0000A7DA8D4FBF1DA4C7CBD6D451F8 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
568 | WGET.DAT | GET | 301 | 65.9.66.47:80 | http://data-cdn.mbamupdates.com/v1/tools/jrt/jrtnewmd5 | unknown | html | 167 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
568 | WGET.DAT | 65.9.66.47:80 | data-cdn.mbamupdates.com | AMAZON-02 | US | unknown |
568 | WGET.DAT | 65.9.66.47:443 | data-cdn.mbamupdates.com | AMAZON-02 | US | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
www.google.com |
| whitelisted |
data-cdn.mbamupdates.com |
| whitelisted |